← Framework library

Gramm-Leach-Bliley Act — FTC Safeguards Rule and Privacy Rule

The FTC Safeguards Rule's required elements of a written information security program, plus the core privacy notice and opt-out duties of the GLBA Privacy Rule. Each control cites the paragraph it derives from.

US Federal Trade Commission (Safeguards Rule); CFPB (Regulation P) · 16 CFR Part 314 as amended 2021 and 2023 (FTC notification duty in force since 13 May 2024); Regulation P, 12 CFR Part 1016 · United States — non-bank financial institutions under FTC jurisdiction (lenders, mortgage brokers, tax preparers, auto dealers, fintechs, payment and wealth services and similar) · Official source

Institutions that maintain customer information about fewer than 5,000 consumers are exempt from 314.4(b)(1) (written risk assessment), (d)(2) (penetration testing and vulnerability assessments), (h) (written incident response plan) and (i) (annual board report) under 16 CFR 314.6 — mark those not applicable with that reason. Banks follow the equivalent Interagency Guidelines rather than the FTC rule. Requirement text is paraphrased; the regulation is authoritative and this tool is not legal advice.
19 of 19 controls
314.4(a) Qualified Individual oversees the information security program high

The institution designates a single Qualified Individual responsible for overseeing, implementing and enforcing its written information security program. The Qualified Individual may be an employee, or work for an affiliate or service provider — in which case the institution keeps responsibility, designates senior personnel to oversee them, and requires the provider to maintain a compliant program.

Safeguards Rule (16 CFR 314) roles-responsibilitiespolicy-governance
314.4(b) Written risk assessment critical

The information security program is based on a written risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information, sets criteria for evaluating and categorising risks, assesses the adequacy of existing controls, and describes how risks will be mitigated or accepted; additional risk assessments are performed periodically.

Safeguards Rule (16 CFR 314) risk-assessment
314.4(c)(1) Access controls on customer information critical

Technical and, as appropriate, physical access controls authenticate and permit access only to authorised users, and limit each user's access to the customer information they need to perform their duties; access is reviewed periodically.

Safeguards Rule (16 CFR 314) access-controlaccess-review
314.4(c)(2) Inventory of data, personnel, devices and systems high

The institution identifies and manages the data, personnel, devices, systems and facilities that enable it to achieve business purposes, in accordance with their relative importance to business objectives and the organisation's risk strategy.

Safeguards Rule (16 CFR 314) inventoryasset-management
314.4(c)(3) Encryption of customer information in transit and at rest critical

All customer information held or transmitted is encrypted, both in transit over external networks and at rest. Where encryption is infeasible, the Qualified Individual may approve effective alternative compensating controls, which must be reviewed.

Safeguards Rule (16 CFR 314) encryption-at-restencryption-in-transit
314.4(c)(4) Secure development and assessment of applications high

Secure development practices are adopted for in-house developed applications used to transmit, access or store customer information, and procedures exist for evaluating, assessing or testing the security of externally developed applications the institution uses.

Safeguards Rule (16 CFR 314) secure-developmentsdlc
314.4(c)(5) Multi-factor authentication for any individual accessing information systems critical

Multi-factor authentication is implemented for any individual accessing any information system, unless the Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls.

Safeguards Rule (16 CFR 314) mfaauthentication
314.4(c)(6) Secure disposal within two years and periodic review of retention high

Customer information is securely disposed of no later than two years after the last date it was used to provide a product or service to the customer, unless it is needed for business operations or other legitimate purposes, required by law, or targeted disposal is infeasible; the data retention policy is reviewed periodically to minimise unnecessary retention.

Safeguards Rule (16 CFR 314) data-deletiondata-retentionmedia-disposal
314.4(c)(7) Change management medium

Procedures for change management govern changes to information systems and networks.

Safeguards Rule (16 CFR 314) change-management
314.4(c)(8) Monitoring and logging of authorised user activity high

Policies, procedures and controls monitor and log the activity of authorised users and detect unauthorised access to, use of, or tampering with customer information by those users.

Safeguards Rule (16 CFR 314) loggingmonitoring
314.4(d) Continuous monitoring, or annual penetration tests and six-monthly vulnerability assessments critical

The effectiveness of safeguards is regularly tested or monitored. For information systems this means continuous monitoring, or annual penetration testing plus vulnerability assessments (including systemic scans) at least every six months, whenever there are material changes, and whenever circumstances may have a material impact.

Safeguards Rule (16 CFR 314) pen-testvulnerability-managementsecurity-testing
314.4(e) Security awareness training and qualified security personnel high

Personnel receive security awareness training updated to reflect risks identified by the risk assessment; qualified information security personnel (employed or via a provider) manage the program; and those personnel receive security updates and training sufficient to address relevant risks, with their knowledge of changing threats verified.

Safeguards Rule (16 CFR 314) trainingawareness
314.4(f) Oversight of service providers critical

Service providers are overseen by taking reasonable steps to select and retain providers capable of maintaining appropriate safeguards, requiring them by contract to implement and maintain such safeguards, and periodically assessing them based on the risk they present and the continued adequacy of their safeguards.

Safeguards Rule (16 CFR 314) vendor-managementthird-party
314.4(g) Evaluate and adjust the program medium

The information security program is evaluated and adjusted in light of testing and monitoring results, material changes to operations or business arrangements, the results of risk assessments, or any other circumstances that may have a material impact on it.

Safeguards Rule (16 CFR 314) policy-governancerisk-assessment
314.4(h) Written incident response plan critical

A written incident response plan is designed to promptly respond to and recover from any security event materially affecting customer information. It addresses the plan's goals, internal response processes, clear roles and decision-making authority, internal and external communications, remediation of identified weaknesses, documentation and reporting of events, and evaluation and revision after events.

Safeguards Rule (16 CFR 314) incident-response
314.4(i) Annual written report to the board high

The Qualified Individual reports in writing, regularly and at least annually, to the board of directors or equivalent governing body — or to a senior officer if there is no board — on the overall status of the program and compliance with the Safeguards Rule, and on material matters such as risk assessment, risk management decisions, service provider arrangements, testing results, security events and recommended changes.

Safeguards Rule (16 CFR 314) board-oversightpolicy-governance
314.4(j) Notify the FTC of notification events affecting 500 or more consumers critical

When the institution discovers a notification event — unauthorised acquisition of unencrypted customer information — involving the information of at least 500 consumers, it notifies the FTC through its online form as soon as possible and no later than 30 days after discovery, including the types of information involved, the date or range of the event, the number of consumers affected and a general description.

Safeguards Rule (16 CFR 314) breach-notification
Reg P 1016.4-1016.6 Initial and annual privacy notices high

Customers receive a clear and conspicuous privacy notice when the customer relationship begins and annually for as long as it continues — unless the annual-notice exception applies (sharing only within the exceptions and no change to policies) — describing the categories of nonpublic personal information collected and disclosed, the categories of recipients, information-sharing practices, the right to opt out, and how the information is protected.

Privacy Rule (Reg P) privacy-notice
Reg P 1016.7-1016.10 Opt-out of sharing with nonaffiliated third parties high

Before disclosing nonpublic personal information to a nonaffiliated third party outside the statutory exceptions, the institution gives the consumer notice and a reasonable opportunity to opt out (for example 30 days and a toll-free number or online form), and honours opt-outs promptly.

Privacy Rule (Reg P) consentopt-out-of-salethird-party